CVE-2025-54948
Trend Micro Apex One OS Command Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 9 critical vulnerabilities and 85 high-priority updates requiring immediate attention.
Trend Micro Apex One OS Command Injection Vulnerability - Active in CISA KEV catalog.
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Git Link Following Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Improper Privilege Management Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Authentication Bypass Vulnerability - Active in CISA KEV catalog.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Meta Platforms WhatsApp Incorrect Authorization Vulnerability - Active in CISA KEV catalog.
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This...
A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability allows remote code execution (RCE) due to improper v...
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affe...
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earlier. If exploited, a remote unauthenticated attacke...
A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution and reading of system files. This issue aff...
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges.
In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability
Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Vacron Camera ping Command Injection Remote Code Execution Vulnerability
A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints
ESPHome is a system to control microcontrollers remotely through Home Automation systems
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability
Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass
Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device values of the product and stop the operations of programs by using the obtained credential information
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features
A vulnerability was detected in RemoteClinic up to 2
A vulnerability was found in RemoteClinic up to 2
In monitor_hang, there is a possible memory corruption due to use after free
In mbrain, there is a possible memory corruption due to use after free
There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing a DSB file with Digilent DASYLab
There is a deserialization of untrusted data vulnerability in Digilent DASYLab
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check
A vulnerability was detected in TOTOLINK A702R 4
A flaw has been found in TOTOLINK A702R 4
A vulnerability has been found in TOTOLINK A702R 4
A vulnerability was found in TOTOLINK A702R 4
A vulnerability was determined in TOTOLINK A702R 4
A weakness has been identified in Tenda AC20 16
A vulnerability was determined in Tenda CH22 1
A vulnerability was identified in Tenda CH22 1
Cross-Site Request Forgery (CSRF) vulnerability in AkΔ±nsoft QR MenΓΌ allows Cross Site Request Forgery
In Modem, there is a possible out of bounds write due to an incorrect bounds check
In BootROM, there is a possible missing validation for Certificate Type 0
In BootRom, there is a possible unchecked write address
In BootRom, there's a possible unchecked command index
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection
A weakness has been identified in alaneuler batteryKid up to 2
There is an out of bounds write vulnerability due to improper bounds checking resulting in invalid data when parsing a DSB file with Digilent DASYLab
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsing a DSB file with Digilent DASYLab
There is an out of bounds write vulnerability due to improper bounds checking in displ2
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid source address when parsing a DSB file with Digilent DASYLab
There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab
Realtek RTL8811AU rtwlanu
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values containing credentials or other secrets
In Modem, there is a possible out of bounds read due to an incorrect bounds check
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured
An issue was discovered in rust-ffmpeg 0
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the deviceβs event log
A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b
A security flaw has been discovered in Campcodes Online Learning Management System 1
A weakness has been identified in Campcodes Online Learning Management System 1
A security vulnerability has been detected in D-Link DIR-852 1
A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1
A security flaw has been discovered in Campcodes/SourceCodester Courier Management System 1
A security vulnerability has been detected in Campcodes Online Feeds Product Inventory System 1
A vulnerability was detected in Campcodes Online Learning Management System 1
A flaw has been found in itsourcecode Sports Management System 1
A vulnerability has been found in itsourcecode Sports Management System 1
A vulnerability was found in itsourcecode Sports Management System 1
A vulnerability was determined in itsourcecode Sports Management System 1
A weakness has been identified in Campcodes Hospital Management System 1
A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1
Improper Validation of Certificate with Host Mismatch vulnerability in AkΔ±nsoft QR MenΓΌ allows HTTP Response Splitting
A vulnerability was found in Campcodes Online Learning Management System 1
A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1
A security flaw has been discovered in SourceCodester Hotel Reservation System 1
A security vulnerability has been detected in itsourcecode Apartment Management System 1
A vulnerability was detected in itsourcecode Apartment Management System 1
A flaw has been found in Campcodes Computer Sales and Inventory System 1
A vulnerability was found in Campcodes Farm Management System 1
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1
A vulnerability was detected in SourceCodester Online Farm Management System 1
A vulnerability was determined in itsourcecode Student Information Management System 1